Institutions adopting SCOPE 2.2 should start with the institutional pilot guide for workshop flow and runbooks/ for operator procedures, then use this page for production wiring and CI. Live IdP, WORM Object Lock, and remote ledger authority remain external (see definition_of_done.md).
- Configure and version-pin
policy/files for local role assignments and scope boundaries - Map lab personnel to reviewer roles; generate Ed25519 keypairs and register public keys
- Build and sign an authorization manifest (
SCOPE_AUTHORIZATION_MANIFEST_PATH+ public key); ensurepolicy_signing_key_registry.yamllists an active key - Integrate AKTA review triggers via
scope akta revieworscope packet create - Enable production mode (
SCOPE_PRODUCTION_MODE=true) with OIDC IdP (SCOPE_OIDC_JWKS_URLorSCOPE_OIDC_PUBLIC_KEY_PEM) and org RBAC (SCOPE_ENFORCE_RBAC=true) - Wire Postgres ledger (
SCOPE_LEDGER_DATABASE_URL/SCOPE_POSTGRES_URL); do not use SQLite in production withoutSCOPE_ALLOW_SQLITE_LEDGER_IN_PRODUCTION=1 - Enforce grants at runtime via PF-Core or equivalent
- Archive SCOPE ledger events with PCS release packages
- Run the institutional CI profile before promoting a release
Authoritative template: env.institutional.example. Summary also in production_deployment.md. Minimum set:
| Variable | Required |
|---|---|
SCOPE_PRODUCTION_MODE=true |
yes |
SCOPE_OIDC_JWKS_URL or SCOPE_OIDC_PUBLIC_KEY_PEM |
yes (live IdP material) |
SCOPE_OIDC_ISSUER / SCOPE_OIDC_AUDIENCE |
recommended |
SCOPE_TENANT_POLICY_MAP |
yes |
SCOPE_POLICY_DIR |
yes |
SCOPE_ARTIFACT_STORE_ROOT |
yes |
SCOPE_LEDGER_DATABASE_URL or SCOPE_POSTGRES_URL |
yes (institutional) |
SCOPE_ISSUER_SIGNING_KEY / SCOPE_ISSUER_PUBLIC_KEY |
yes |
SCOPE_AUTHORIZATION_MANIFEST_PATH |
yes |
SCOPE_AUTHORIZATION_MANIFEST_PUBLIC_KEY |
yes |
Check readiness without contacting IdP:
python scripts/validate_institutional_env.pyDev-only keys (never production): python scripts/generate_dev_institutional_keys.py --out-dir .scope/dev-keys --exports
# Clone into ../siblings (set clone URLs first), or point at existing checkouts:
eval "$(bash scripts/clone_sibling_contracts.sh)"
# or:
export PF_CORE_REPO_PATH=/path/to/pf-core
export PCS_CORE_REPO_PATH=/path/to/pcs-core
export AKTA_REPO_PATH=/path/to/akta
export SCOPE_LEDGER_DATABASE_URL=postgresql://scope:scope@127.0.0.1:5432/scope
export SCOPE_REQUIRE_LIVE_CONTRACTS=true # fail-closed if any sibling missing
bash scripts/ci.sh --institutionalGitHub Actions org/repo variables for job institutional:
| Variable | Role |
|---|---|
PF_CORE_REPO (alias PF_CORE_REPO_CLONE_URL) |
Clone URL |
PCS_CORE_REPO (alias PCS_CORE_REPO_CLONE_URL) |
Clone URL |
AKTA_REPO (alias AKTA_REPO_CLONE_URL) |
Clone URL |
*_REPO_PATH |
Self-hosted pre-mounted paths |
SCOPE_REQUIRE_LIVE_CONTRACTS=true |
Fail-closed when siblings missing |
Job dependency-audit is fail-closed on release/** branches. Live IdP JWKS endpoints and production private keys remain human-provided deploy secrets.
- Who reviewed (role, ID, identity assurance level, authority checks, credential evidence on REST)
- What scope was approved and what remained blocked
- Signing assurance level on decisions and grants
- When grants expired and whether runtime respected grants
- Trust root hashes binding policy and key registry (signed authorization manifest)
SCOPE provides the authorization trail; it does not certify scientific correctness or regulatory compliance.
- runbooks/ — operator procedures and offline gates
- institutional_pilot_guide.md — workshop and lab integration
- pilot_sequence.md — staged deployment modes
- production_deployment.md — REST/IdP/ledger wiring
- trusted_boundary.md — trust assumptions
- limitations.md — in-repo vs external boundaries
- definition_of_done.md — readiness checklist
- adr/0010-institutional-pilot-release-boundaries.md — AS-08 claim boundary
- reviewer_guide.md — role-specific guidance
Offline gates (prefer before institutional CI):
python scripts/run_institutional_offline_gates.py